CVE-2018-5253: High severity Axiosys Bento4 vulnerability
Published Jan 5, 2018
·Updated
The AP4FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.
Affected Software
1 affected component
Axiosys Bento4=1.5.1.0
Event History
Jan 5, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5253?
CVE-2018-5253 is classified as having a medium severity level due to its potential to cause denial of service through an infinite loop.
2
How do I fix CVE-2018-5253?
To fix CVE-2018-5253, update Bento4 to the latest version that addresses this vulnerability.
3
What software is affected by CVE-2018-5253?
CVE-2018-5253 affects Bento4 version 1.5.1.0 specifically.
4
Can CVE-2018-5253 be exploited remotely?
Yes, CVE-2018-5253 can be exploited remotely via malicious MP4 files.
5
What type of vulnerability is CVE-2018-5253?
CVE-2018-5253 is a denial of service vulnerability caused by an infinite loop in the processing of crafted MP4 files.